Inline Tweet Sharer – Twitter Sharing Plugin Security & Risk Analysis

wordpress.org/plugins/inline-tweet-sharer

Inline Tweet Sharer is a plugin that allows you to easily and simply create links to share your content on twitter. These links share whatever the anc …

300 active installs v2.6.9 PHP + WP 3.8+ Updated Dec 11, 2025
gutenberg-readysocial-mediasocial-media-marketingsocial-media-promotiontwitter
100
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 15, 2023
Safety Verdict

Is Inline Tweet Sharer – Twitter Sharing Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

Inline Tweet Sharer – Twitter Sharing Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 15, 2023Updated 3mo ago
Risk Assessment

The inline-tweet-sharer plugin, version 2.6.9, exhibits a generally good security posture with several strengths. The plugin demonstrates a commitment to secure coding practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped outputs. Furthermore, the absence of known unpatched vulnerabilities and no critical or high-severity taint flows are positive indicators. The plugin also correctly utilizes capability checks where necessary.

However, there are some areas that warrant caution. The static analysis revealed no explicit nonce checks, which is a concern for potential CSRF vulnerabilities, especially for any functionality that modifies data or settings. While the overall attack surface is small and appears to have no unprotected entry points, the lack of nonce checks suggests a potential blind spot. The vulnerability history, while currently clear of critical or high-severity issues, does include a past medium-severity Cross-Site Scripting (XSS) vulnerability. This indicates that while the developers have addressed past issues, the potential for input sanitization flaws should remain a point of vigilance.

In conclusion, inline-tweet-sharer v2.6.9 is relatively secure due to its use of prepared statements and good output escaping. The absence of active critical vulnerabilities and a low overall attack surface are commendable. The primary weaknesses are the lack of nonce checks, which could open the door to CSRF attacks, and the past medium XSS vulnerability, which suggests ongoing vigilance is needed regarding input sanitization.

Key Concerns

  • Missing nonce checks
  • Past medium severity XSS vulnerability
Vulnerabilities
1

Inline Tweet Sharer – Twitter Sharing Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-24005medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Inline Tweet Sharer <= 2.5.3 - Authenticated (Admin+) Stored Cross-Site Scripting

Feb 15, 2023 Patched in 2.6 (342d)
Code Analysis
Analyzed Mar 16, 2026

Inline Tweet Sharer – Twitter Sharing Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
16 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
4
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

89% escaped18 total outputs
Attack Surface

Inline Tweet Sharer – Twitter Sharing Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[inlinetweet] inline-tweet-sharer.php:52
WordPress Hooks 11
filtermce_external_pluginsinc\deprecated.php:12
filtermce_buttonsinc\deprecated.php:13
filtermce_external_pluginsinc\tinymce.php:22
filtermce_buttonsinc\tinymce.php:23
actioninitinline-tweet-sharer.php:28
actionadmin_menuinline-tweet-sharer.php:41
actionadmin_initinline-tweet-sharer.php:42
actionadmin_enqueue_scriptsinline-tweet-sharer.php:43
actionadmin_initinline-tweet-sharer.php:44
actionwp_enqueue_scriptsinline-tweet-sharer.php:48
actionplugins_loadedinline-tweet-sharer.php:54
Maintenance & Trust

Inline Tweet Sharer – Twitter Sharing Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version
Downloads41K

Community Trust

Rating100/100
Number of ratings11
Active installs300
Developer Profile

Inline Tweet Sharer – Twitter Sharing Plugin Developer Profile

Rhys Wynne

13 plugins · 7K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
476 days
View full developer profile
Detection Fingerprints

How We Detect Inline Tweet Sharer – Twitter Sharing Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/inline-tweet-sharer/inline-tweet-sharer.css/wp-content/plugins/inline-tweet-sharer/inline-tweet-sharer-admin.css
Script Paths
/wp-content/plugins/inline-tweet-sharer/inline-tweet-sharer.js
Version Parameters
inline-tweet-sharer/inline-tweet-sharer.css?ver=inline-tweet-sharer/inline-tweet-sharer-admin.css?ver=inline-tweet-sharer/inline-tweet-sharer.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-its-share-urldata-its-tweet-text
JS Globals
inline_tweet_sharer_js
Shortcode Output
<ahref="javascript:void(0)"class="inline-tweet-sharer-link"
FAQ

Frequently Asked Questions about Inline Tweet Sharer – Twitter Sharing Plugin